PT-2019-7549 · E107 · E107

Published

2019-05-24

·

Updated

2019-05-29

·

CVE-2016-10753

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions e107 version 2.1.2
Description The issue allows PHP Object Injection, which can result in SQL injection. This is because the usersettings.php file uses the unserialize function without an HMAC.
Recommendations For e107 version 2.1.2, consider updating to a version where the unserialize function is properly secured, or as a temporary workaround, restrict access to the usersettings.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10753

Affected Products

E107